2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-11468MEDIUM5.7When folding a long comment in an email header containing exclusively unfoldable characters, the parenthesis would not b...
CVE-2025-66902HIGH7.5An input validation issue in in Pithikos websocket-server v.0.6.4 allows a remote attacker to obtain sensitive informati...
CVE-2025-66692HIGH7.5A buffer over-read in the PublicKey::verify() method of Binance - Trust Wallet Core before commit 5668c67 allows attacke...
CVE-2025-63648HIGH7.5A NULL pointer dereference in the dacp_reply_playqueueedit_move function (src/httpd_dacp.c) of owntone-server commit b7e...
CVE-2025-63647HIGH7.5A NULL pointer dereference in the parse_meta function (src/httpd_daap.c) of owntone-server commit 334beb allows attacker...
CVE-2025-59466HIGH7.5We have identified a bug in Node.js error handling where "Maximum call stack size exceeded" errors become uncatchable wh...
CVE-2025-59465HIGH7.5A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unha...
CVE-2025-59464HIGH7.5A memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freein...
CVE-2025-57156HIGH7.5NULL pointer dereference in the dacp_reply_playqueueedit_clear function in src/httpd_dacp.c in owntone-server through co...
CVE-2025-57155HIGH7.5NULL pointer dereference in the daap_reply_groups function in src/httpd_daap.c in owntone-server through commit 5e6f19a ...
CVE-2025-55132MEDIUM5.3A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` ev...
CVE-2025-55131HIGH7.1A flaw in Node.js's buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using...
CVE-2025-55130CRITICAL9.1A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions u...
CVE-2025-66803MEDIUM4.8Race condition in the turbo-frame element handler in Hotwired Turbo before 8.0.x causes logout operations to fail when d...
CVE-2025-56005CRITICAL9.8An undocumented and unsafe feature in the PLY (Python Lex-Yacc) library 3.11 allows Remote Code Execution (RCE) via the ...
CVE-2025-67263MEDIUM6.1Abacre Retail Point of Sale 14.0.0.396 is affected by a stored cross-site scripting (XSS) vulnerability in the Clients m...
CVE-2025-67261MEDIUM6.5Abacre Retail Point of Sale 14.0.0.396 is vulnerable to content-based blind SQL injection. The vulnerability exists in t...
CVE-2025-55423CRITICAL9.8A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the contr...
CVE-2025-33233HIGH7.8NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerability where an attacker could cause code injection. ...
CVE-2025-33231MEDIUM6.7NVIDIA Nsight Systems for Windows contains a vulnerability in the application’s DLL loading mechanism where an attacker ...
CVE-2025-33230HIGH7.3NVIDIA Nsight Systems for Linux contains a vulnerability in the .run installer, where an attacker could cause an OS comm...
CVE-2025-33229HIGH7.3NVIDIA Nsight Visual Studio for Windows contains a vulnerability in Nsight Monitor where an attacker can execute arbitra...
CVE-2025-33228HIGH7.3NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command in...
CVE-2025-67824MEDIUM6.1The WorklogPRO - Jira Timesheets plugin in the Jira Data Center before 4.24.2-jira9, 4.24.2-jira10 and 4.24.2-jira11 all...
CVE-2025-65482CRITICAL9.8An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitra...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now